Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
magikarp
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Anonymity Smackdown: NSA vs. Tor
(blog.erratasec.com)
3 points
by
magikarp
13y ago
|
0 comments
32.
▲
Feds are Suspects in New Malware That Attacks Tor Anonymity
(wired.com)
186 points
by
magikarp
13y ago
|
33 comments
33.
▲
by
magikarp
13y ago
I feel this is something that many a [insert security software in which critical bug was recently found here] has gone through. We've been following full disclosure principles and fixing bugs as they come for the past couple of years.
34.
▲
by
magikarp
13y ago
Whether Cryptocat programmers suck or not, I've seen worse errors from better programmers. I'm not sure what's the metric to follow here when it comes to correlating these two items.
35.
▲
by
magikarp
13y ago
As the lead developer for Cryptocat, I must say this is really a great example of how to write a post-mortem for a security bug. Sophos bloggers are always worth reading.
36.
▲
by
magikarp
13y ago
> Cryptocat did not give those warnings. Cryptocat said it was secure. This is just not true. There are ample warnings on the front page of the website as well as on the login screen on the app. Cryptocat has never said it's complet
37.
▲
by
magikarp
13y ago
That line isn't used in anything sensitive.
38.
▲
SSL Report: crypto.cat
(ssllabs.com)
2 points
by
magikarp
13y ago
|
0 comments
39.
▲
Adopting Accessibility and Ease of Use as Security Properties
(arxiv.org)
1 points
by
magikarp
13y ago
|
0 comments
40.
▲
by
magikarp
13y ago
That was a great read.
41.
▲
by
magikarp
13y ago
Why haven't signed browser plugins been mentioned yet? They significantly aid with the problem of code delivery. With Chrome, Firefox, and Safari, it is possible to deliver web apps as signed, local browser plugins, applications and extensi
42.
▲
Why Developing for Firefox is Torturous
(log.nadim.cc)
3 points
by
magikarp
13y ago
|
1 comments
43.
▲
by
magikarp
13y ago
I don't think I have it anymore. I didn't save a copy.
44.
▲
by
magikarp
13y ago
Well, I guess you're just slightly more pessimistic and I'm slightly more optimistic. I respect your viewpoint, though. :-)
45.
▲
by
magikarp
13y ago
> When this response was written, the blog post said nothing of the sort. In fact, in that point the text has not been changed whatsoever. Allow me to quote from the blog post: "In fact, I believe that it is necessary to deliver JavaSc
46.
▲
by
magikarp
13y ago
> Yes, but just because it can be mitigated doesn't mean that it is mitigated. Sure, but I just want to point to the fact that this is a solvable problem . A lot of people talk as if it is some sort of insurmountable obstacle, whereas
47.
▲
by
magikarp
13y ago
That may very well be the case, but isn't this a solvable problem? Just like apps made in C need to be protected against buffer overflows, apps made in JS need to be protected against XSS. Both are reasonable threats that can be mitigated.
48.
▲
by
magikarp
13y ago
> Generally speaking, the fact that JS source is pushed down on every access means that there's no way for you to actually review it. The blog post says that it is necessary for code to be loaded as a local, signed browser plugin. This
49.
▲
by
magikarp
13y ago
Okay. But XSS is class of bugs that has nothing to do with code delivery, and that is quite possible to mitigate. So overall, the problem of code delivery is still addressed to a notable (if not complete) extent with the use of downloadable
50.
▲
by
magikarp
13y ago
Aren't those trust boundary issues also present in every other piece of downloadable software, such as Tor for example? When you download a signed plugin, what's the difference from downloading Tor?
51.
▲
by
magikarp
13y ago
There are actually other changes. I recommend you re-read the post. Edit: Thank you for re-reading! :-)
52.
▲
by
magikarp
13y ago
The blog post was updated to reflect post-2011 reality right before you posted this comment. You should give it a re-read.
53.
▲
Show HN: A single app for notes, tasks and passwords
(bluenote.io)
2 points
by
magikarp
13y ago
|
1 comments
54.
▲
Show HN: Bluenote, a notes, task and password manager for Mac
(bluenote.io)
3 points
by
magikarp
14y ago
|
2 comments
55.
▲
by
magikarp
14y ago
Well said.
56.
▲
by
magikarp
14y ago
It's a bug in the Chrome 25 Beta. Will be fixed on stable release.
57.
▲
by
magikarp
14y ago
Cryptocat is a browser plugin. You need to download it like everything else. The source code is on Github. I swear upon my father's grave I will never do something so dishonest and evil towards everyone who has supported Cryptocat, the most
58.
▲
by
magikarp
14y ago
Sorry. I am very stressed and am knocked into full self-defense/damage control mode. Not sure I am in a state to meet people IRL at the moment.
59.
▲
by
magikarp
14y ago
If anyone knows a good lawyer in Montreal, please let me know! nadim@nadim.cc
60.
▲
by
magikarp
14y ago
It would be nice if you could meet me for coffee and say this to my face, friend. I am trying to protect myself and my open source project, which, by the way, has been audited countless times and has progressed greatly towards security. If
More ›